4.3
CVSSv2

CVE-2012-1902

Published: 06/04/2012 Updated: 18/01/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

show_config_errors.php in phpMyAdmin 3.4.x prior to 3.4.10.2, when a configuration file does not exist, allows remote malicious users to obtain sensitive information via a direct request, which reveals the installation path in an error message about this missing file.

Vulnerable Product Search on Vulmon Subscribe to Product

phpmyadmin phpmyadmin 3.4.3.0

phpmyadmin phpmyadmin 3.4.3.1

phpmyadmin phpmyadmin 3.4.8.0

phpmyadmin phpmyadmin 3.4.9.0

phpmyadmin phpmyadmin 3.4.5.0

phpmyadmin phpmyadmin 3.4.6.0

phpmyadmin phpmyadmin 3.4.3.2

phpmyadmin phpmyadmin 3.4.4.0

phpmyadmin phpmyadmin 3.4.10.0

phpmyadmin phpmyadmin 3.4.10.1

phpmyadmin phpmyadmin 3.4.0.0

phpmyadmin phpmyadmin 3.4.1.0

phpmyadmin phpmyadmin 3.4.2.0

phpmyadmin phpmyadmin 3.4.7.0

phpmyadmin phpmyadmin 3.4.7.1